Pages:
Author

Topic: Site's Security Grade: A- (Read 2442 times)

hero member
Activity: 826
Merit: 1000
°^°
March 06, 2014, 10:00:27 AM
#28
A? good joke
donator
Activity: 1218
Merit: 1079
Gerald Davis
March 05, 2014, 06:16:33 PM
#27
How come?

IMO there'd be a much higher chance of it causing problems than preventing an attack.

Try to think of an attack that the forum's current HSTS setup wouldn't protect against.

How would it cause a problem?  If you don't have the ability to operate using https you simply shouldn't be operating (this goes for any site which needs to secure communication between server and client).   If something results in you losing your TLS cert for a period of time it would be better to not operate the site until it is restored.   If anything the only useful value for HSTS would be infinite (i.e. NEVER UNTIL THE END OF TIME CONNECT TO THIS DOMAIN INSECURELY) but since that is not an option a very long HSTS value is used as a proxy.
administrator
Activity: 5222
Merit: 13032
March 05, 2014, 06:10:48 PM
#26
How come?

IMO there'd be a much higher chance of it causing problems than preventing an attack.

Try to think of an attack that the forum's current HSTS setup wouldn't protect against.
hero member
Activity: 728
Merit: 500
hero member
Activity: 728
Merit: 500
March 04, 2014, 03:01:50 PM
#24
So how about implementing HSTS?

It is implemented, just not long-term.
How come?
administrator
Activity: 5222
Merit: 13032
March 04, 2014, 02:52:45 PM
#23
So how about implementing HSTS?

It is implemented, just not long-term.
hero member
Activity: 728
Merit: 500
March 04, 2014, 02:20:28 PM
#22
So how about implementing HSTS?
hero member
Activity: 728
Merit: 500
February 24, 2014, 05:50:09 PM
#21
I forget what the problem was specifically and there's no way to look back either.
sr. member
Activity: 462
Merit: 250
February 24, 2014, 05:11:42 PM
#20
It used to be an F. It's not perfect, but it's been improved a great deal.

Why was it an F? What could possibly have been done?
legendary
Activity: 2674
Merit: 2965
Terminated.
February 24, 2014, 04:16:04 PM
#19
Now it is okay, but an A+ is always welcome.
hero member
Activity: 728
Merit: 500
February 24, 2014, 01:38:39 PM
#18
It used to be an F. It's not perfect, but it's been improved a great deal.
copper member
Activity: 3948
Merit: 2201
Verified awesomeness ✔
February 24, 2014, 11:55:47 AM
#17

Funny thing. It's not fixed at all.




newbie
Activity: 42
Merit: 0
February 24, 2014, 04:25:20 AM
#16
legendary
Activity: 910
Merit: 1000
★YoBit.Net★ 350+ Coins Exchange & Dice
February 23, 2014, 07:11:15 AM
#15
good to see its fixed..
hero member
Activity: 868
Merit: 1000
February 22, 2014, 11:46:55 PM
#14
LOL.

BCB
vip
Activity: 1078
Merit: 1002
BCJ
February 22, 2014, 10:14:36 PM
#13
Excellent. How much more do we have to wait until it has been updated/upgraded? This leaves so much room for a potential second hack.
Looks like it's been fixed.

Very nice.
hero member
Activity: 728
Merit: 500
February 22, 2014, 06:57:02 PM
#12
Excellent. How much more do we have to wait until it has been updated/upgraded? This leaves so much room for a potential second hack.
Looks like it's been fixed.
legendary
Activity: 2674
Merit: 2965
Terminated.
February 12, 2014, 12:50:39 AM
#11
Excellent. How much more do we have to wait until it has been updated/upgraded? This leaves so much room for a potential second hack.
BCB
vip
Activity: 1078
Merit: 1002
BCJ
Pages:
Jump to: